ST/SEO / TECH LIST
DiscoverBestFree toolsSkillsMCPLaunch
Search⌘ KSubmit ↗
Privacy

Your data,
plainly explained.

What we collect, why we use it and the choices available to directory visitors and product submitters.

Effective 20 July 2026Version 1.0
On this page01Controller02Scope and data collected03Purposes and legal bases04Public listing information05Click analytics06Cookies and local storage07Service providers08International transfers09Retention10Your rights11Security12Children13Policy changes
Current setup

We do not use advertising cookies or cross-site behavioural tracking. Public click statistics are aggregated by product and destination. Product submissions are stored for formatting and publication.

01

Controller

The controller of personal data processed through SEO Tech List is Wojciech Skrzek, trading as WebMoose, VAT ID (NIP) PL6462926700, address ul. Zapolskiej 22/12, 43-100 Tychy, Poland.

For privacy requests, contact hello@seotechlist.com or write to the address above. We have not appointed a Data Protection Officer.

02

Scope and data collected

Directory visitors

Our hosting and security infrastructure may process IP address, request time, requested URL, browser and device information, approximate network location, security signals and diagnostic logs. We do not create public visitor profiles.

Product submitters and makers

We process the contact name or maker name, email address, product name and type, website and GitHub URLs, pitch, description, selected plan, submission and payment status, uploaded logo and screenshot, correspondence, publication history and information needed to handle complaints or claims.

Listing claimants and owners

We process the claimant’s name, work email, role, email-verification state, claim review history, listing permissions, authenticated session records and listing changes. If you sign in with Google or GitHub, we receive the provider account identifier, verified email, display name, profile image and limited profile information. For GitHub repository verification, we temporarily use the OAuth access token to check your permission level for the exact repository being claimed; we do not store that access token. If you choose DNS verification, we store the requested TXT record name, a one-way hash of its random verification token, check timestamps and the verification result. The DNS record itself is public and is read through Cloudflare’s DNS resolver.

Public sources

For editorial listings we may use publicly available company, product and repository information, including GitHub metadata. Where public information identifies a natural person, it may constitute personal data.

03

Purposes and legal bases

PurposeLegal basis
Receive, review, publish and maintain submissions; communicate with makers; deliver Community or Premium services.Performance of a contract or steps requested before a contract — Article 6(1)(b) GDPR.
Invoices, tax records, consumer obligations and legally required disclosures.Compliance with a legal obligation — Article 6(1)(c) GDPR.
Service security, abuse prevention, debugging, editorial integrity, claims, aggregated click reporting and improving the directory.Our legitimate interests — Article 6(1)(f) GDPR.
Optional marketing communication or non-essential storage technologies, if introduced.Consent — Article 6(1)(a) GDPR. Consent may be withdrawn at any time.

Providing information marked as required in the submission form is necessary for us to review the product. Without it, we cannot process the submission. We do not use submitted data for automated decisions producing legal or similarly significant effects.

04

Public listing information

After publication, product name, maker or company name, descriptions, categories, pricing label, compatibility, product media, website and GitHub links and selected public repository metadata may be displayed. Contact email, payment details and internal formatting notes are not published.

If a public maker name identifies you and you need it corrected or removed, contact us. We will balance the request with applicable legal obligations and legitimate editorial interests.

05

Click analytics

When a visitor opens a listed website or GitHub repository, the application records the product identifier and whether the destination was the website or GitHub. To avoid counting repeated clicks from the same visitor on the same day, the application creates a one-way daily hash from request and browser signals. The raw IP address and user-agent are not stored with the click event, the hash changes each day and it is used only for deduplication and aggregated maker reporting.

Cloudflare may still process ordinary request and security data when delivering the tracking endpoint, as described under Service providers.

06

Cookies and local storage

The public directory currently does not use advertising cookies or non-essential analytics cookies. Strictly necessary technologies may be used for security, traffic delivery and protected administration. The administration area and owner dashboard use secure, HTTP-only session cookies after successful authentication. Owner sessions are stored in a revocable form and normally expire after 30 days.

Where enabled, Cloudflare Turnstile processes technical and security signals to prevent spam. Turnstile can operate without advertising cookies or local storage. If we later introduce non-essential analytics or marketing technologies, we will update this Policy and request consent where required before activating them.

07

Service providers and recipients

We use Cloudflare for website delivery, Workers execution, D1 database storage, R2 media storage, security and optional Turnstile verification. Cloudflare processes data on our behalf and may also process limited data under its own responsibilities for security and network operation.

We use Resend to deliver transactional messages such as submission confirmations, publication notices, claim verification and passwordless sign-in links. Resend receives the recipient address and message content needed to provide that service.

If selected by you, Google or GitHub provides account authentication. We request only the account identity and verified email scopes needed for sign-in. GitHub repository ownership checks also use repository permission information for the listing you choose to claim. These providers process the authentication request under their own privacy terms.

When Premium checkout is enabled, Stripe may process payer identification, billing and payment information. We will not store complete payment-card numbers. We may also disclose data to professional advisers, hosting or maintenance contractors and public authorities where necessary and legally permitted.

We do not sell personal data.

08

International transfers

Some providers operate globally and may process data outside the European Economic Area. Where required, transfers are protected using an applicable adequacy decision, Standard Contractual Clauses or another safeguard recognized by GDPR. Information about relevant safeguards may be requested using the contact details above.

09

Retention

  • Pending or withdrawn submissions: generally up to 24 months after submission or withdrawal, unless a shorter period is requested or longer retention is needed for a dispute or abuse prevention.
  • Published listing data and media: while the listing remains active, followed by up to 3 years for claims, audit and restoration purposes.
  • Payment and accounting records: for the period required by tax and accounting law, generally 5 years calculated under applicable Polish rules.
  • Correspondence and complaints: for the time needed to resolve the matter and generally up to 3 years afterwards.
  • Security and diagnostic logs: according to operational need and provider settings, generally no longer than 12 months unless an incident requires longer retention.
  • Authentication and ownership records: active owner sessions normally expire after 30 days; expired OAuth authorization states are deleted automatically; DNS challenges expire after 48 hours and completed or expired challenge details are normally deleted after 30 days; account and listing-permission records are retained while owner access remains active and then as needed for security, claims and audit.
  • Aggregated statistics: may be retained longer where they no longer identify an individual.

These periods may be extended where necessary to establish, exercise or defend legal claims or comply with law.

10

Your rights

Subject to the conditions in GDPR, you may request access to your data, rectification, erasure, restriction, portability, or object to processing based on legitimate interests. Where processing relies on consent, you may withdraw it at any time without affecting earlier lawful processing.

Send requests to hello@seotechlist.com. We may need to verify your identity and will respond within the period required by law. You also have the right to lodge a complaint with the President of the Personal Data Protection Office (UODO) in Poland or another competent supervisory authority.

11

Security

We use access controls, encrypted connections, signed administration sessions, request validation, anti-spam checks and restricted storage access. No internet service can guarantee absolute security. Please do not submit secrets, credentials or unnecessary personal information through product descriptions or uploaded media.

12

Children

Product submission and paid services are intended for adults acting professionally or on behalf of a business. We do not knowingly request personal data from children. If you believe a child submitted data, contact us so we can assess and remove it where appropriate.

13

Policy changes

We may update this Policy when the service, providers or legal requirements change. The latest version and effective date are published on this page. Material changes affecting existing submitters may also be communicated by email where appropriate.

Privacy request or question?hello@seotechlist.com ↗
ST/SEO / TECH LIST

The curated discovery layer for AI search tools, agent skills and open-source SEO infrastructure.

Discover

All productsBest toolsFree SEO toolsAI SEO toolsAgent skillsOpen source

Launch

Submit a productManage a listingPricingFAQ

Categories

AI visibilityTechnical SEOMCP serversAI visibility guideAI crawler checker
© 2026 SEO Tech List / WebMoose
TermsPrivacyContact